harden: ignore a nonce the page supplies with eth_sendTransaction (closes #404)
A site could fix the nonce of the transaction the user was asked to sign: the same nonce as a pending transaction, at a higher fee, replaces it, and a nonce above the account's next one leaves the new transaction stuck behind a gap. `nonce` is no longer one of the fields taken from the request, so the transaction always gets the account's next nonce from the network, and that is the nonce the approval screen shows and the popup signs. Model: opus-5-5
This commit was merged in pull request #434.
This commit is contained in:
@@ -45,6 +45,15 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: A nonce the site supplies with `eth_sendTransaction` is ignored
|
||||
([#404](https://git.eeqj.de/sneak/AutistMask/issues/404)). It was passed on to
|
||||
the transaction, so a site could replace one of the user's pending
|
||||
transactions (same nonce, higher fee) or leave the new one stuck behind a gap,
|
||||
and the approval screen showed it as a bare number. `nonce` is no longer one
|
||||
of the fields taken from the request in `src/shared/approvalTx.js`, so the
|
||||
transaction always gets the account's next nonce from the node, and that is
|
||||
the nonce the approval screen shows and the popup signs.
|
||||
|
||||
- 2026-10-04: Remembered site permissions are held by full origin
|
||||
([#402](https://git.eeqj.de/sneak/AutistMask/issues/402)). `allowedSites` and
|
||||
`deniedSites` stored the hostname alone, so a grant to `https://dapp.example`
|
||||
|
||||
Reference in New Issue
Block a user